#cisa-kev
7 articles
This archive collects 7 articles tagged cisa-kev published between April 19, 2026 and June 17, 2026, giving security teams a focused view of how this topic has appeared across ZCyberNews coverage. Recent coverage references CVE-2026-48907, CVE-2026-42271, and CVE-2024-57728, with each report tied to the specific vulnerability context available in the source article. The affected-scope signals emphasize government, technology, and media across North america, United states, and EU, helping readers compare exposure patterns without adding claims beyond the archive data. Severity coverage includes 2 critical, 3 high, and 2 medium reports.
CRITICALCISA Adds Joomla JCE Flaw CVE-2026-48907 to KEV Catalog
CISA warns of active exploitation of CVE-2026-48907, a CVSS 10.0 improper access control flaw in Widget Factory Joomla Content Editor (JCE) allowing unauthenticated PHP code...
HIGHCVE-2026-42271: LiteLLM Flaw Exploited in the Wild, CISA Adds to KEV
CISA added CVE-2026-42271 (CVSS 8.7) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against BerriAI LiteLLM deployments.
MEDIUMCVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEV
CISA added CVE-2026-9082 (CVSS 6.5) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against all supported Drupal Core versions.
HIGHCVE-2024-57728: SimpleHelp Path Traversal Lets Admins Upload
CISA adds CVE-2024-57728 to Known Exploited Vulnerabilities: SimpleHelp path traversal via zip slip allows admin users to upload arbitrary files and execute code. Due May 8, 2026.
HIGHCVE-2025-2749: Kentico Xperience Path Traversal Under Active Exploit
CISA adds CVE-2025-2749 to KEV catalog: Kentico Xperience path traversal lets authenticated Staging Sync Server upload arbitrary files. Due date for federal agencies: May 4, 2026.
MEDIUMNIST NVD Enrichment Change Creates CVSS Gap for 80% of CVEs
NIST now enriches only 15-20% of CVEs under new policy as of April 2026, leaving 80% without CVSS scores or product mappings.
CRITICALMicrosoft Office Excel Flaw Exploited in Active Attacks
CISA orders federal agencies to patch CVE-2009-0238, a 17-year-old Microsoft Office Excel remote code execution flaw, by April 28, 2026, due to active exploitation.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.